PT-2026-106601 · Linux · Linux

CVE-2026-98272

·

Published

2026-10-06

·

Updated

2026-10-06

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
net: mvpp2: prevent buffer overflow in page pool allocation
The per‑processor buffering scheme is supported only if the number of pools (nrxqs * 2) does not exceed MVPP2 BM MAX POOLS (8). This is already checked in mvpp2 probe() during the initial activation of percpu pools.
However, mvpp2 change mtu() may later call mvpp2 bm switch buffers(priv, true) without this check, which can lead to an out-of-bounds access in the priv->page pool array in mvpp2 bm init(). The array is sized to hold MVPP2 PORT MAX RXQ entries, and mvpp2 get nrxqs() may return exactly that value. The per-CPU scheme then doubles it to nrxqs * 2, exceeding the array bounds.
Check that the hardware version is MVPP22 or newer and that the number of pools (nrxqs * 2) does not exceed MVPP2 BM MAX POOLS before switching to per-CPU mode.
Found by Linux Verification Center (linuxtesting.org) with SVACE.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-98272

Affected Products

Linux